易想团购(easethink) v1.4 /ajax.php...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 漏洞相关文件 #### 1. /ajax.php ``` if($_REQUEST['act']=='count_buy_total') { require_once APP_ROOT_PATH."system/libs/cart.php"; $region_id = intval($_REQUEST['region_id']); //配送地区 $delivery_id = intval($_REQUEST['delivery_id']); //配送方式 $account_money = floatval($_REQUEST['account_money']); //余额 $ecvsn = $_REQUEST['ecvsn']?$_REQUEST['ecvsn']:''; $ecvpassword = $_REQUEST['ecvpassword']?$_REQUEST['ecvpassword']:''; $payment = intval($_REQUEST['payment']); $all_account_money = intval($_REQUEST['all_account_money']); $user_id = intval($GLOBALS['user_info']['id']); $session_id = session_id(); $goods_list = $GLOBALS['db']->getAll("select * from ".DB_PREFIX."deal_cart where session_id='".$session_id."' and user_id=".$user_id); $result = count_buy_total($region_id,$delivery_id,$payment,$account_money,$all_account_money,$ecvsn,$ecvpassword,$goods_list); $GLOBALS['tmpl']->assign("result",$result); $html = $GLOBALS['tmpl']->fetch("inc/cart/cart_total.html"); $data = $result; $data['html'] =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息